CVE-2023-47440

Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gladysassistant:gladys_assistant:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:30

Type Values Removed Values Added
References () https://blog.moku.fr/cve/ - Third Party Advisory () https://blog.moku.fr/cve/ - Third Party Advisory
References () https://blog.moku.fr/cves/CVE-2023-47440/ - Third Party Advisory () https://blog.moku.fr/cves/CVE-2023-47440/ - Third Party Advisory
References () https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7 - Patch () https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7 - Patch

12 Dec 2023, 18:06

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:gladysassistant:gladys_assistant:*:*:*:*:*:*:*:*
First Time Gladysassistant
Gladysassistant gladys Assistant
References () https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7 - () https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7 - Patch
References () https://blog.moku.fr/cve/ - () https://blog.moku.fr/cve/ - Third Party Advisory
References () https://blog.moku.fr/cves/CVE-2023-47440/ - () https://blog.moku.fr/cves/CVE-2023-47440/ - Third Party Advisory

07 Dec 2023, 18:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-07 18:15

Updated : 2024-11-21 08:30


NVD link : CVE-2023-47440

Mitre link : CVE-2023-47440

CVE.ORG link : CVE-2023-47440


JSON object : View

Products Affected

gladysassistant

  • gladys_assistant
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')